Welcome to our

Cyber Security News Aggregator

.

Cyber Tzar

provide a

cyber security risk management

platform; including automated penetration tests and risk assesments culminating in a "cyber risk score" out of 1,000, just like a credit score.

Microsoft acquires firmware analysis company ReFirm, eying edge IoT security

published on 2021-06-02 17:58:41 UTC by Joe Uchill
Content:
Microsoft acquired ReFirm Labs Wednesday in a bid to bolster its operational technology security offerings. (Photo by Drew Angerer/Getty Images)

Microsoft acquired ReFirm Labs Wednesday in a bid to bolster its operational technology security offerings.

ReFirm provides drag-and-drop automated firmware analysis, which Microsoft hopes will provide security insight for industrial IoT products, where security personnel often struggle to look inside built-in hardware.

“I run vulnerability and pen testing for the operating system group at Microsoft, and the quality of reports that were coming out the ReFirm automated system was starting to rival the things that I would pay a highly-skilled professional to generate,” said David Weston, Microsoft director of enterprise and OS security in Azure Edge and platform.

Microsoft’s ReFirm acquisition follows June’s acquisition of CyberX, an agentless OT network defense system. Weston hopes that the products will synergistically bolster the defenses of industrial systems. And while much of Microsoft’s announced focus has been on industrial IoT, he sees worthy uses for anything with firmware, including desktops.

ReFirm was founded in 2017 as an offshoot of the popular open-source Binwalk product. Weston said he anticipated work on Binwalk would continue unabated.

The ReFirm announcement comes less than a month after the Department of Homeland Security named “vulnerabilities below the operating system” a key focus of future cybersecurity efforts. Thomas Ruoff and Boyden Rohner, methodology branch chief and associate director of CISA respectively, announced an agency campaign at the RSA Conference last month to increase firmware security.

The Cybersecurity and Infrastructure Security Agency announcement specifically mentions automated code analysis as a key component, a goal Weston backs.

“Firmware is kind of the software that we politely ignore today,” he said. “Mostly we don’t have capabilities around it.”

The post Microsoft acquires firmware analysis company ReFirm, eying edge IoT security appeared first on SC Media.

Article: Microsoft acquires firmware analysis company ReFirm, eying edge IoT security - published over 3 years ago.

https://www.scmagazine.com/home/security-news/cloud-security/microsoft-acquires-firmware-analysis-company-refirm-eying-edge-iot-security/   
Published: 2021 06 02 17:58:41
Received: 2021 06 02 18:00:27
Feed: SC Magazine
Source: SC Media
Category: News
Topic: Cyber Security
Views: 3

Custom HTML Block

Click to Open Code Editor